I love Cloudflare – there I have said it! If you are looking for a way to keep your site secure and performant then Cloudflare is the way to go. Today I am going to be looking at just one aspect of Cloudflare and what it can do for you – Zero Trust.

What is Cloudflare?

I like to think of Cloudflare as the Swiss Army knife of cloud-based tools. It offers solutions for a variety of things from security to performance to domain registration to content delivery all packaged in an easy to understand and use web-based interface. And,

How did they manage to get that?

So I received the above message to my phone last week. There were several things that were interesting about it:

  • it was supposedly from Apple (it isn’t)
  • whoever sent it had my full name
  • they also had my mobile number.

This was obviously a scam as Apple a) wouldn’t send notifications like this and b) definitely wouldn’t send you to a site called “”.

I'm pretty careful about who has my mobile number although getting my name is pretty easy so I'm left wondering just who or what has been compromised to allow this information to become available to spammers.

Ignorance of Security isn’t Acceptable in 2014

I noticed the other day that on one of my accounts for a company I have done business with in the past (lets call them “Marketing File” as that is what they are called) was using what I considered to be a weak password. When I went to change it I found that I couldn’t do it through the web interface but had to call their support department. At this point I could hear the sound of faint alarm bells in the back of my head.

When I called the number and explained that I wanted to change my password

A Google Sized Problem

20120805-203034.jpgAs of June 2012 Gmail has 425 million active users. That’s seven times the population of the UK and one and a half times the population of the US, so it’s a pretty sizeable number of people. I am an active user, the rest of my household are users, as is my mother-in-law. This gives a good idea of the cross section of people using Gmail: young, old, male, female, tech-savvy and not so.

About a month ago my mother-in-law's Gmail account was hacked but not only was the password changed but also all the reset data. This is